Microsoft Certified: Azure Administrator AssociateImplement and manage storageMedium

A company is configuring an Azure File Share to be accessed by both Windows and Linux virtual machines within an Azure Virtual Network. The solution must support identity-based authentication for both operating systems. You need to recommend the authentication method for the Azure File Share.

  1. AAzure Active Directory (Azure AD) Kerberos authentication for hybrid identities.
  2. BStorage account key authentication.
  3. CAzure Active Directory Domain Services (Azure AD DS) authentication.
  4. DOn-premises Active Directory Domain Services (AD DS) authentication.
Show answer & explanation

Correct answer: A. Azure Active Directory (Azure AD) Kerberos authentication for hybrid identities.

Azure Active Directory (Azure AD) Kerberos authentication for hybrid identities allows both Windows and Linux clients joined to Azure AD (or hybrid joined) to access Azure File Shares with identity-based authentication. This provides a unified and secure authentication experience for a mixed environment.

Why the other options are wrong

  • B. Storage account key authentication is not identity-based and grants full access to the share, which is not suitable for granular access control and security best practices.
  • C. Azure AD DS authentication is suitable for cloud-native clients but might require specific configurations for hybrid identities and Linux clients in a mixed environment.
  • D. On-premises AD DS authentication is primarily for clients joined to an on-premises domain, making it less ideal for native Azure VM clients without complex networking.

Azure AD Kerberos authentication for hybrid identities

Azure AD Kerberos authentication for hybrid identities enables identity-based access to Azure File Shares for both Windows and Linux clients that are either Azure AD-joined or hybrid Azure AD-joined, without requiring a traditional domain controller.

  • Supports both Windows and Linux clients.
  • Leverages Azure AD for identity management.
  • Provides Kerberos authentication without Azure AD DS or on-premises AD DS.
  • Suitable for hybrid environments.
  • Requires specific configuration steps on clients and Azure.

Memory trick: Files authentication: AD DS for traditional, AAD DS for cloud, AAD Kerberos for hybrid, or simple key.

More Implement and manage storage questions